CVE-2016-10706
Versions of the Jetpack plugin before 4.0.3 contain a stored cross-site scripting flaw where shortcodes can be exploited to inject and execute malicious scripts within the WordPress environment.
Based on public CVE data (MITRE/NVD).
CVE · Medium
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2016-10706 | Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 4.0.3 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.1 | < 4.0.3 | 4.0.3 | 2017-04-26 | — |
Versions of the Jetpack plugin before 4.0.3 contain a stored cross-site scripting flaw where shortcodes can be exploited to inject and execute malicious scripts within the WordPress environment.
Based on public CVE data (MITRE/NVD).
No signup, no credit card — enter your URL and get a security report in seconds.